The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11625 | The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 23 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cminds
Cminds video Lessons Manager Cminds video Lessons Manager Pro |
|
| CPEs | cpe:2.3:a:creativemindssolutions:video_lessons_manager_pro:*:*:*:*:*:wordpress:*:* |
cpe:2.3:a:cminds:video_lessons_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:cminds:video_lessons_manager_pro:*:*:*:*:*:wordpress:*:* |
| Vendors & Products |
Creativemindssolutions
Creativemindssolutions video Lessons Manager Creativemindssolutions video Lessons Manager Pro |
Cminds
Cminds video Lessons Manager Cminds video Lessons Manager Pro |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:42:16.189Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24713
No data.
Status : Analyzed
Published: 2021-11-23T20:15:09.820
Modified: 2026-01-23T13:22:56.473
Link: CVE-2021-24713
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD